ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Google addresses 107 Android vulnerabilities, including two zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-48633CVE-2025-48572CVE-2025-48631

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48572
+1 in the same advisory: …48633
Local Privilege Escalation in Android Framework Under Active Exploitation

CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%.

Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe.

7.8
group max
<1% KEV
  • Google Android (Framework component)
massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device)
CVE-2025-48631
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion.

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
6.5<1%
  • google android
Full article601 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The company’s latest security update contains the second-highest number of defects patched so far this year.

Listen to this article

0:00

Learn more.

Google's Washington, DC, regional office is seen at dusk on August 11, 2024, in Reston, VA. (Photo by J. David Ake/Getty Images)

Google disclosed two actively exploited zero-day vulnerabilities Monday, which it addressed among a total of 107 defects in the company’s monthly security update for Android devices.

The zero-days — CVE-2025-48633 and CVE-2025-48572 — are both high-severity defects affecting the Android framework, which attackers can exploit to access information and escalate privileges, respectively. Google said both vulnerabilities, which had not been added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog as of Monday afternoon, may be under limited, targeted exploitation.

Google’s public vulnerability disclosure and reporting program for Android has been uneven this year. While the company typically issues dozens of security patches each month, Google reported no vulnerabilities in July and October, just six in August and two vulnerabilities in November. 

Google did not respond to questions about the occasional lulls in vulnerability disclosure and hasn’t described any changes to its process that might explain the lower numbers in some months this year. 

The company’s latest security update contains the second-highest number of vulnerabilities patched so far this year, followed by the 120 defects it addressed in September

Google said the most severe vulnerability this month — CVE-2025-48631 — is a critical defect affecting the framework, which attackers can exploit to achieve remote denial of service with no additional execution privileges required. 

The Android security bulletin for December includes two patch levels — 2025-12-01 and 2025-12-05 — allowing Android partners to address common vulnerabilities on different devices. Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.

The primary security update contains 37 vulnerabilities affecting the framework, including CVE-2025-48631, and 14 defects affecting the system. 

The second patch addresses nine vulnerabilities affecting the kernel, including four that are designated critical. The update also contains fixes for two Arm components defects, four Imagination Technologies bugs, 17 vulnerabilities affecting MediaTek components, 13 Unisoc components flaws, and 11 Qualcomm components, including two rated critical. 

Google said source code for all vulnerabilities addressed in this month’s Android security bulletin will be released to the Android Open Source Project repository by Wednesday.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-december-2025/